CVE Database
/

CVE-2008-7097

Back to search

CVE-2008-7097

Published: Aug 27, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

krate-index-sql-injection(44670)
vdb-entry
x_refsource_XF
6312
exploit
x_refsource_EXPLOIT-DB
30842
vdb-entry
x_refsource_BID
31548
third-party-advisory
x_refsource_SECUNIA
48338
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now